Storing and using multipurpose secret data
Abstract
A system and method improves operational performance of a computer by enhancing digital security with an added electronic circuit. The electronic circuit stores sensitive data in an un-erasable state such that the sensitive data may not be altered. The electronic circuit limits transfer of the sensitive data only once after each power-up or after each reset of the computer. The electronic circuit prevents access to the sensitive data by an authorized program. The electronic circuit utilizes its own storage medium and a random access memory, the latter of which can receive and store the sensitive data from the non-transitory computer storage medium. The method uses a software driver and a copy-of-copy of first security key obtained from the sensitive data stored on the electronic circuit. The software driver installs a software module on the computer using the copy-of-copy of first security key to encrypt each installed file.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of improving operational performance of a computer and protecting the computer from malware by using an encrypted input list holding a name of a computer file or a name of a computer file extension of the computer file, the method comprising the steps of:
storing the computer file on a non-transitory computer storage medium accessible to the computer; storing the encrypted input list on the non-transitory computer storage medium; configuring the encrypted input list so that it is not necessary for operation of the computer; storing a computer security key on a random access memory accessible to the computer; integrating a kernel software driver into an operating system on the computer, the kernel software driver configured to grant or deny permission to perform a file operation on the computer file; and including programming code in the kernel software driver, the programming code operable for implementing steps of:
receiving a request made on the computer by a user to perform the file operation on the computer file;
reading the encrypted input list from the non-transitory computer storage medium of the computer and using the computer security key to decrypt the encrypted input list deriving therefrom an unencrypted input list;
determining whether or not the user is verified by the kernel software driver through a login software module associated with the kernel software driver;
scanning the unencrypted input list for a computer file name or for a computer file extension of the computer file; and
when either the name of the computer file or the name of the computer file extension of the computer file is found in the unencrypted input list, then allowing the user that is verified to perform the file operation on the computer file.
2 . The method of claim 1 , further comprising the step of configuring the programming code to limit the file operation to one selected from the group consisting of edit, open, save, delete, copy, move, execute, read, and write.
3 . The method of claim 1 , further comprising the step of configuring the programming code to require the kernel software driver to implement the step of saving the computer file on the non-transitory computer storage medium as a disabled file when neither the name of the computer file nor the computer file extension is found in the unencrypted input list or when the user is not verified.
4 . A method of improving operational performance of a computer and protecting the computer, the method comprising the steps of:
storing an encrypted date and timeframe on a non-transitory computer storage medium, the encrypted date and timeframe comprising a starting date, a starting time, and an ending time; storing a computer security key in a random access memory; integrating a kernel software driver into an operating system on the computer, the kernel software driver operable to control input and output access to a computer file stored in the non-transitory computer storage medium and to control access to a computer folder stored in the non-transitory computer storage medium; including in the kernel software driver, programming code operable for implementing steps of:
receiving at the kernel software driver each request received by the computer to access a computer file or a folder;
reading the encrypted date and timeframe from the non-transitory computer storage medium and using the computer security key to decrypt the encrypted date and timeframe to produce an unencrypted date and timeframe;
reading the current date and time provided by a clock in the computer;
determining whether or not a current date and time is within the unencrypted date and timeframe;
when the current date and time is within the unencrypted date and timeframe, then the kernel software driver allowing access to the computer file or access to the folder; and
when the current date and time is not within the unencrypted date and timeframe, then the kernel software driver preventing access to the computer file or access to the folder.
5 . The method of claim 4 , further comprising the steps of:
providing an encrypted input list stored on the non-transitory computer storage medium; configuring the encrypted input list so that is not necessary for operation of the computer; and storing the encrypted date and timeframe in the encrypted input list.
6 . The method of claim 4 , further comprising the step of storing the encrypted date and timeframe in metadata of a computer file.
7 . The method of claim 4 , further comprising the step of storing the encrypted date and timeframe in metadata of a folder.
8 . A method of improving operational performance of a computer and protecting the computer using an encrypted input list holding a name of a computer file or a name of a computer file extension, the method comprising the steps of:
storing an encrypted input list on a non-transitory computer storage medium accessible by a computer; configuring the encrypted input list so that it is not necessary for operation of the computer; storing a computer security key on a random access memory accessible by the computer; integrating a kernel software driver into an operating system of the computer, the kernel software driver configured to control the storing of a computer file; including programming code in the kernel software driver, the programming code operable for implementing steps of:
receiving a request on the computer for storing a computer file on the non-transitory computer storage medium;
reading the encrypted input list from the non-transitory computer storage medium and using the computer security key to decrypt the encrypted input list to produce an unencrypted input list;
determining whether or not a user is an authorized user as a result of having been verified by the kernel software driver through a login software module associated with the kernel software driver;
scanning the unencrypted input list for the name of the computer file or the computer file extension; and
saving the computer file on the non-transitory computer storage medium when the name of the computer file or when the computer file extension is found in the unencrypted input list, and when the user has been verified as the authorized user.
9 . The method of claim 8 , further comprising the step of configuring the programming code to require the kernel software driver to implement the step of saving the computer file on the non-transitory computer storage medium as a disabled file when the name of the computer file or the computer file extension is not found in the unencrypted input list or when the user is not logged in.
10 . The method of claim 8 , further comprising the step of configuring the programming code to require the kernel software driver to implement steps of:
requesting the user to login when the user has not been verified; and
saving the computer file on the non-transitory computer storage medium when a user responds to a request to login with a correct credential and becomes the authorized user.Join the waitlist — get patent alerts
Track US2021004472A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.